html-preview / html-preview.github.io

HTML Preview for git-forge Repositories
https://html-preview.github.io/
Apache License 2.0
13 stars 5 forks source link

Add privacy warning #6

Open Rudxain opened 5 hours ago

Rudxain commented 5 hours ago

If a repo script persistently stores sensitive data (as cookie, localStorage, etc...), then other repos opened by the user will also have access to this data. This isn't inherently a problem of bypassing CORS, so it should be mentioned as an additional risk (both in the README and the index)

I haven't tested if this "vulnerability" actually works, but I assume it's likely that it can be easily exploited

hoijui commented 2 hours ago

Sorry, I did not get notifications for this repo, even though I created it. :/ (now I do) ... and you can now do this yourself! :-)